CVE-2026-74398: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
In the Linux kernel, the following vulnerability has been resolved:
ipv6: addrconf: bail out of dadfailure when state is no longer POSTDAD
addrconfdadfailure() transitions ifp->state from DAD to POSTDAD via addrconfdadend(), which drops ifp->lock on return. The lock is re-acquired after netinforatelimited(). A concurrent ipv6deladdr() can take the lock in that window, set ifp->state to DEAD and run listdelrcu(&ifp->iflist).
addrconfdadfailure() then overwrites DEAD with ERRDAD at errdad: and schedules a new dadwork. The work calls ipv6deladdr() again, hitting the already-poisoned list entry:
general protection fault: 0000 [#1] SMP NOPTI CPU: 4 PID: 217 Comm: kworker/4:1 Workqueue: ipv6addrconf addrconfdadwork RIP: 0010:ipv6deladdr+0xe9/0x280 RAX: dead000000000122 Call Trace: addrconfdadstop+0x113/0x140 addrconfdadwork+0x28c/0x430 processonework+0x1eb/0x3b0 workerthread+0x4d/0x400 kthread+0x104/0x140 retfromfork+0x35/0x40
Fold the addrconfdadend() logic into addrconfdadfailure() under a single ifp->lock critical section. The STABLEPRIVACY branch temporarily drops ifp->lock around address regeneration, so at lockerrdad: verify the state is still POSTDAD before transitioning to ERRDAD; bail out otherwise to avoid overwriting a state set by another path while the lock was released.